The AI Office Gained Real Enforcement Power This Month
The European Commission's AI Office received full enforcement and inspection authority over general purpose AI providers on 2 August 2026, ending a year in which the strictest part of the EU AI Act existed only on paper. The office can now request internal documentation from a GPAI provider, run its own technical evaluation of that provider's model, order corrective measures, and, in the most serious cases, force a model off the EU market entirely.
The European Commission describes the office's mandate as covering every general purpose model already sold or offered inside the EU, whether that model comes from a US lab, a European startup, or any other provider. Until this month, that mandate had no working enforcement machinery behind it.
The Rules Were Already Law For A Year
The GPAI obligations under the AI Act took legal effect in August 2025, a full year before enforcement became possible. Providers were required to maintain technical documentation, publish a summary of the data used to train their models, and put a copyright compliance policy in place, among other duties set out in the Act.
Article 99 of the AI Act sets out the penalties that apply when a provider breaches those duties, but the AI Office needed its own operational powers before it could open a case, request evidence, or impose a fine. Those powers only arrived on 2 August 2026, so for twelve months the obligations carried no practical consequence.
Three Penalty Tiers Define The Real Exposure
The AI Act sets three separate penalty tiers, and which one applies depends on which obligation a provider is found to have breached.
| Penalty tier | Maximum fine | What triggers it |
|---|---|---|
| Highest tier | 35 million euro or 7 percent of global annual turnover | Prohibited AI practices banned outright under the Act |
| Middle tier | 15 million euro or 3 percent of global annual turnover | Breach of GPAI obligations or other Act requirements |
| Lowest tier | 7.5 million euro or 1 percent of global annual turnover | Supplying false, incomplete or misleading information to the AI Office |
A Vendor's Model Can Now Be Pulled Mid Contract
An EU or UK business that has built a product or an internal workflow on top of a frontier model now carries a vendor risk that did not functionally exist a month ago. The AI Office can open a technical evaluation of that exact model, and if it finds a breach it can order the provider to change the model or withdraw it from the EU market while a contract with that business is still running.
That exposure sits outside the fine itself. A corrective order or a market withdrawal can change how a model behaves, or remove it altogether, on a timeline the enterprise using it does not control and may not see coming until the change has already happened.
Enterprises Should Ask Their Vendors Now, Not Later
Enterprises should ask their frontier model vendor directly whether the AI Office has already made contact, requested documentation, or opened any form of review, since a provider under evaluation today may face a corrective order or a market restriction within months.
A second, equally practical step is to keep a fallback model or vendor ready rather than assume that a model's current behavior remains compliant indefinitely. The AI Office's new powers mean that assumption is no longer safe for any business whose product or workflow depends on a single GPAI provider.
Read next: Brussels Can Now Pull the Model You Build On | August 2 Is When the EU AI Fines Become Real



